On Wed, 16 Feb 2011 00:29:24 +0200, Gleb Paharenko
<[email protected]> wrote:
Hi!
Is there any way to disable remote control of agents from the server?
My
clients do not won't to be compromised through the agents in case of
compromise of OSSEC servers. As server can update agents configs it
is
theoretically possible to read sensitive information by specifying
which
file to read.
Not natively. Do they also take measures to prevent the backup
infrastructure and package management system from reading files they
shouldn't? And do those systems also chroot and run under limited,
privileged separated processes? I think it's good to look at the bigger
picture to see where OSSEC may fit in the overall risk.
--
Michael Starks
[I] Immutable Security
http://www.immutablesecurity.com